Following Oliver Salzburg's suggestion I run mountvol on cmd and got the unique drive identifier that widnows reports is associated with F:\. I then searched for any handles referring to this identifier in Sysinternals Process Explorer but again nothing popped up.

Using Process Explorer you can easily determine what services are run by that service host by simply hovering with your mouse over the process with that PID (1020).
–
Oliver Salzburg♦Feb 29 '12 at 16:30